Ability to Restore Availability and Access
This is a security requirement that organisations be able to bring personal data back online and make it accessible again in a timely way after something goes wrong, such as a system failure, outage, or physical damage. In practice it typically means having recovery measures like backups and a plan to get systems working again. It is one of several security capabilities expected when handling personal data.
One of the technical and organisational measures identified in Article 32 GDPR (security of processing), requiring controllers and processors, as appropriate and subject to a risk-based assessment, to be able to restore the availability of and access to personal data in a timely manner following a physical or technical incident. This capability is generally supported by recovery-oriented controls such as backup regimes, resilience arrangements, and incident response and recovery processes, and per ICO guidance it forms part of demonstrating appropriate security. The Regulation does not prescribe specific technologies or fixed recovery timeframes; what is 'appropriate' and 'timely' depends on factors including the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to individuals. The evidence here does not address the equivalent UK GDPR position in detail beyond ICO guidance, and readers should verify the current Article 32 text and applicable guidance.
Why it matters
The ability to restore the availability of and access to personal data is one of the security capabilities expressly identified in Article 32 GDPR, and it addresses a scenario that most organisations will face at some point: personal data becoming unavailable following a physical or technical incident such as a system failure, outage, or physical damage. Where individuals depend on an organisation to hold and process their data, an inability to recover that data in a timely way can itself constitute a security failing and, depending on the circumstances, may have consequences for the people whose data is affected.
This requirement reflects the GDPR's treatment of security as extending beyond confidentiality to include availability and resilience. A breach under the Regulation is not limited to unauthorised disclosure; it can also involve accidental loss of access to personal data. Demonstrating that recovery measures are in place is therefore part of showing appropriate security and, per ICO guidance, part of demonstrating accountability. What counts as 'timely' and 'appropriate' is not fixed by the Regulation and depends on a risk-based assessment, so organisations should document their reasoning rather than assume any single standard applies universally.
The boundary of this concept is important: Article 32 does not prescribe specific technologies or fixed recovery timeframes, and the evidence here does not detail equivalent positions beyond ICO guidance. Readers should verify the current Article 32 text and applicable regulatory guidance, and recognise that expectations may vary with the nature, scope, context, and purposes of the processing and the risks to individuals.
Who it's relevant to
Inside Ability to Restore Availability and Access
Common questions
Answers to the questions practitioners most commonly ask about Ability to Restore Availability and Access.